US2026081893A1PendingUtilityA1

Application context via endpoint-aware traffic for enhanced security

Assignee: PALO ALTO NETWORKS INCPriority: Sep 13, 2024Filed: Sep 13, 2024Published: Mar 19, 2026
Est. expirySep 13, 2044(~18.1 yrs left)· nominal 20-yr term from priority
H04L 63/0263H04L 63/20
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques for providing application context via endpoint-aware traffic for enhanced security are disclosed. In some embodiments, a system/process/computer program product for providing application context via endpoint-aware traffic for enhanced security includes collecting process information for a process at an endpoint; injecting the process information as metadata into network traffic associated with the process to generate endpoint-aware traffic; and processing the endpoint-aware traffic at a security platform or a security service to access more comprehensive information about the endpoint environment to apply a security policy based on a contextual application identifier (App-ID).

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system, comprising:
 a processor configured to:
 collect process information for a process at an endpoint; 
 inject the process information as metadata into network traffic associated with the process to generate endpoint-aware traffic; and 
 process the endpoint-aware traffic at a security platform or a security service to access more comprehensive information about the endpoint to apply a security policy based on a contextual application identifier (App-ID); and 
   a memory coupled to the processor and configured to provide the processor with instructions.   
     
     
         2 . The system of  claim 1 , wherein the security platform includes a firewall, a network gateway firewall (NGFW), and/or another network device, and wherein the security service includes a cloud-based security service. 
     
     
         3 . The system of  claim 1 , wherein the security platform and/or the security service monitors the endpoint-aware traffic, and wherein the security platform includes a firewall, a network gateway firewall (NGFW), and/or another network device, and wherein the security service includes a cloud-based security service. 
     
     
         4 . The system of  claim 1 , wherein indicators are configured on the endpoint to collect the process information at the endpoint using an agent executed on the endpoint. 
     
     
         5 . The system of  claim 1 , wherein indicators are configured on the endpoint to collect the process information at the endpoint, and wherein the process information includes a process identifier (PID), a process parent identifier (PPID), and a process name. 
     
     
         6 . The system of  claim 1 , wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy. 
     
     
         7 . The system of  claim 1 , wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy based on the contextual App-ID. 
     
     
         8 . The system of  claim 1 , wherein identification of the contextual App-ID is performed prior to a start of a new session associated with network traffic for the new session, wherein the identification of the contextual App-ID prior to the start of the new session reduces risks associated with data leakage by preventing a forwarding of any packets from the new session based on the contextual App-ID and the security policy. 
     
     
         9 . The system of  claim 1 , wherein the processor is further configured to:
 extract the process information and automatically group a plurality of traffic sessions sharing a common process identifier (PID) and/or a common parent process identifier (PPID) to be associated with a single application; and   wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying a security policy based on a contextual App-ID for the plurality of traffic sessions.   
     
     
         10 . The system of  claim 1 , wherein the processor is further configured to:
 extract the process information and automatically group a plurality of traffic sessions sharing a common process identifier (PID) and/or a common parent process identifier (PPID) to be associated with a single application;   wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy based on a contextual App-ID for the plurality of traffic sessions; and   wherein if any of the network traffic within the group matches one or more existing App-ID signatures for identifying an application, then each of the plurality of traffic sessions associated with the group are automatically identified as being associated with the application.   
     
     
         11 . A method, comprising:
 collecting process information for a process at an endpoint;   injecting the process information as metadata into network traffic associated with the process to generate endpoint-aware traffic; and   processing the endpoint-aware traffic at a security platform or a security service to access more comprehensive information about the endpoint to apply a security policy based on a contextual application identifier (App-ID).   
     
     
         12 . The method of  claim 11 , wherein indicators are configured on the endpoint to collect the process information at the endpoint using an agent executed on the endpoint. 
     
     
         13 . The method of  claim 11 , wherein indicators are configured on the endpoint to collect the process information at the endpoint, and wherein the process information includes a process identifier (PID), a process parent identifier (PPID), and a process name. 
     
     
         14 . The method of  claim 11 , wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy. 
     
     
         15 . The method of  claim 11 , wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy based on the contextual App-ID. 
     
     
         16 . The method of  claim 11 , wherein identification of the contextual App-ID is performed prior to a start of a new session associated with network traffic for the new session, wherein the identification of the contextual App-ID prior to the start of the new session reduces risks associated with data leakage by preventing a forwarding of any packets from the new session based on the contextual App-ID and the security policy. 
     
     
         17 . The method of  claim 11 , further comprising:
 extracting the process information and automatically grouping a plurality of traffic sessions sharing a common process identifier (PID) and/or a common parent process identifier (PPID) to be associated with a single application; and   wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying a security policy based on a contextual App-ID for the plurality of traffic sessions.   
     
     
         18 . The method of  claim 11 , further comprising:
 extracting the process information and automatically grouping a plurality of traffic sessions sharing a common process identifier (PID) and/or a common parent process identifier (PPID) to be associated with a single application;   wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy based on a contextual App-ID for the plurality of traffic sessions; and   wherein if any of the network traffic within the group matches one or more existing App-ID signatures for identifying an application, then each of the plurality of traffic sessions associated with the group are automatically identified as being associated with the application.   
     
     
         19 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:
 collecting process information for a process at an endpoint;   injecting the process information as metadata into network traffic associated with the process to generate endpoint-aware traffic; and   processing the endpoint-aware traffic at a security platform or a security service to access more comprehensive information about the endpoint to apply a security policy based on a contextual application identifier (App-ID).   
     
     
         20 . The computer program product of  claim 19 , wherein indicators are configured on the endpoint to collect the process information at the endpoint using an agent executed on the endpoint.

Join the waitlist — get patent alerts

Track US2026081893A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.